Security alert: WSUS remote code execution vulnerability
ID: 171d3f5e-f94e-501e-83eb-78f1d68bac33
STIX ID: report--171d3f5e-f94e-501e-83eb-78f1d68bac33
Feed Name: Expel Blog
Threat Score
**CVE-2025-59287 (WSUS RCE) — Active exploitation observed; patch immediately.** A critical remote code execution vulnerability in Windows Server Update Service is being actively exploited against internet-exposed WSUS servers to run SYSTEM-level PowerShell commands that enumerate host and domain information and exfiltrate it (observed to webhook.site); organizations should patch WSUS instances promptly even if not believed to be internet-exposed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
